
REVIEWS.io for WooCommerce Security & Risk Analysis
wordpress.org/plugins/reviewscouk-for-woocommerceREVIEWS.io, helps eCommerce merchants to collect & display verified product and company reviews. A Google Licensed partner.
Is REVIEWS.io for WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100REVIEWS.io for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The reviewscouk-for-woocommerce plugin v1.5.5 exhibits a generally good security posture based on the static analysis. The complete absence of unprotected entry points, including AJAX handlers and REST API routes, is a significant strength. The plugin also demonstrates robust coding practices with 100% of SQL queries using prepared statements and a very high percentage of output escaping. The presence of nonce and capability checks, even if limited in number, further contributes to its secure design.
However, the static analysis does not cover all potential attack vectors, and the taint analysis results are listed as 0 flows analyzed, indicating that deeper, dynamic analysis might not have been performed or did not uncover specific unsanitized paths. While the vulnerability history shows only one past medium-severity vulnerability (Cross-site Scripting) and no currently unpatched issues, it is important to note that the last reported vulnerability was very recent, suggesting that ongoing vigilance is necessary. The presence of a past XSS vulnerability, even if patched, warrants attention for any unescaped outputs or potential input handling flaws that might be missed by static analysis alone.
In conclusion, the plugin has implemented several key security best practices. The absence of critical vulnerabilities and the strong adherence to prepared statements and output escaping are commendable. The primary area for potential concern lies in the limited scope of the taint analysis and the recent history of a medium-severity vulnerability. While the current version appears secure based on the provided data, the plugin's developer should continue to prioritize thorough security testing and rapid patching of any newly discovered issues.
Key Concerns
- Past medium severity vulnerability (XSS)
- Taint analysis not performed or yielded 0 flows
REVIEWS.io for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
REVIEWS.io <= 1.2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
REVIEWS.io for WooCommerce Code Analysis
Output Escaping
REVIEWS.io for WooCommerce Attack Surface
Shortcodes 9
WordPress Hooks 35
Scheduled Events 2
Maintenance & Trust
REVIEWS.io for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
REVIEWS.io for WooCommerce Alternatives
Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More
reviews-feed
No API key required. Display Yelp and Google reviews for any business in a clean, customizable feed on your site.
Rich Showcase for Google Reviews
widget-google-reviews
Display up to 10 Google reviews in less than a minute. Continue collecting new reviews. No limits on connected places, widgets, shortcodes and blocks.
WP Social Ninja – Embed Social Feeds, User Reviews & Chat Widgets
wp-social-reviews
Add Facebook feeds, Instagram feeds, TikTok feeds, Facebook reviews, WhatsApp Chat, Messenger chat, Testimonial, and others using a single dashboard.
Reviews and Rating – Google Reviews
g-business-reviews-rating
Completely restriction-free Google reviews and rating as Shortcode/Widget. Extensive display options; delicious themes; includes Structured Data.
Reviews Widgets for Google, Yelp & TripAdvisor
fb-reviews-widget
Combine Facebook recommendations with Google, Yelp and TripAdvisor reviews in a widget, block or shortcode. Build a trusted website!
REVIEWS.io for WooCommerce Developer Profile
1 plugin · 1K total installs
How We Detect REVIEWS.io for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/reviewscouk-for-woocommerce/css/admin-style.css/wp-content/plugins/reviewscouk-for-woocommerce/js/admin-script.js/wp-content/plugins/reviewscouk-for-woocommerce/js/widget-options-script.jshttps://cdn.jsdelivr.net/npm/@simonwep/pickr/dist/pickr.min.jsreviewscouk-for-woocommerce/css/admin-style.css?ver=reviewscouk-for-woocommerce/js/admin-script.js?ver=reviewscouk-for-woocommerce/js/widget-options-script.js?ver=HTML / DOM Fingerprints
reviewsio-widget-containerreviewsio-product-widgetdata-reviewsio-store-iddata-reviewsio-product-idreviewsio_data[reviewsio_product_rich_snippet][reviewsio_reviews_widget][reviewsio_nuggets_widget][reviewsio_nuggets_bar_widget]